The organization should run and update a formal documented process for identifying, analysing and evaluating risk that: identifies risks from deliberate and accidental threats that could affect, directly or indirectly, its assets, operations, activities, functions and stakeholders (through threat, vulnerability and criticality analysis); analyses which risks significantly affect its activities and functions, its products and services, the supply chain, the environment and relationships with stakeholders; evaluates and ranks risks into four bands, namely intolerable (treated whatever the cost if the activity is to continue), as low as reasonably practicable (further reduction would cost out of proportion to benefit), tolerable (negligible or handled by routine procedures) and acceptable (taken on or kept by informed decision); and selects, evaluates and monitors controls and treatments against their costs and benefits. To keep the information documented, current and confidential, the organization should: keep checking whether scope, policy and risk assessment still fit the context; re-evaluate risks when things change inside the organization or around it, including its procedures, functions and services, its partnerships and supply chains, and its mutual aid arrangements; re-evaluate controls after risk events through investigation, treatment and management acceptance; weigh the direct and indirect costs and benefits of options that cut risk and raise reliability and resilience; make sure prioritised risks drive how the PAPMS is set up and run; and evaluate how well controls and treatments work.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.